Bank of Baroda Says Cyber Incident Stemmed from Business Email Compromise; Probe Underway amid Claims of 1TB Data Leak
Moneylife Digital Team 28 July 2026
Public sector lender Bank of Baroda (BoB) has disclosed that it is investigating a cybersecurity incident after receiving a communication from an anonymous source claiming access to certain data. The Bank said preliminary findings indicate that the incident involved a business email compromise rather than an intrusion into its core banking infrastructure and asserted that there has been no material impact on its operations, financial performance or business continuity.
 
The disclosure comes amid media reports alleging that a threat actor has published around 1TB of Bank of Baroda data on the dark web, including customer and internal banking documents.
 
According to the Bank's regulatory filing, it immediately activated its cyber incident response and containment protocols after receiving the anonymous communication. It also engaged an independent Indian computer emergency response team (CERT-In) or an empanelled cybersecurity agency of the Reserve Bank of India (RBI) to carry out a comprehensive assessment and investigate the nature and extent of the alleged compromise.
 
Bank of Baroda said the initial assessment suggests the incident is a potential business email compromise, a type of cyberattack in which attackers gain unauthorised access to an employee's email account to steal information or impersonate legitimate users.
 
The lender said the incident is 'not expected to have any material impact' on its operations or financial performance. It added that all core business functions continued to operate normally without disruption while a detailed assessment remains in progress. Appropriate remedial and preventive measures are also being implemented.
 
In a subsequent statement posted on X, the Bank clarified that the compromise involved an employee's email account, resulting in unauthorised access to certain data. It stressed that its core banking systems were neither accessed nor compromised and remain secure. BoB also said it is conducting a comprehensive forensic investigation in coordination with the relevant authorities.
 
Alleged 1TB Data Leak Reported
The disclosure follows reports claiming that a hacker has made around 1TB of Bank of Baroda data freely available on the dark web. In a series of tweets on X, L Srikanth, founder of Cashless Consumer, an advocacy organisation for tech safety, shared some sample data of BoB as available on the dark web.
 
 
His tweets show an alleged dataset including savings and current account records, loan-related information, netbanking user details, non-resident Indian (NRI) and corporate banking records, customer support material and branch and ATM-related documents. He claims that the leaked information contains both customer data and internal banking records spanning multiple branches across India.
 
According to Mr Srikanth, these sample documents allegedly uploaded by the threat actor include branch audit reports, loan appraisal documents, internal communications, vigilance investigation records, bobWorld audit reports and customer application forms containing Aadhaar numbers and photographs. 
 
 
However, the authenticity of these documents has not been independently verified.
 
So far, no threat actor has publicly claimed responsibility for the alleged breach. However, Mr Srikanth reportedly suggested that a relatively new hacking group known as 'TripleX' could be responsible, citing similarities with an earlier attack on Indonesia's state-owned PT Bank Negara Indonesia, where around 2TB of data was allegedly stolen.
 
 
Neither Bank of Baroda nor Indian authorities have confirmed these claims or attributed the incident to any specific threat actor.
 
According to reports, if the current claims are authenticated, the incident could rank among the largest alleged cybersecurity exposures involving an Indian financial institution in terms of the volume of data reportedly leaked. However, experts note that the source of the data, the method of compromise and the authenticity of the entire dataset have yet to be independently established.
 
The latest incident also revives attention on earlier security and compliance issues involving the bank.
 
In October 2023, RBI directed BoB to suspend on-boarding new customers through its bobWorld mobile application (https://www.moneylife.in/article/bank-of-baroda-asked-to-suspend-onboarding-customers-onto-bob-world-mobile-app/72231.html) following supervisory concerns over irregular customer onboarding practices. That issue was unrelated to a cyberattack and was linked to the misuse of customer accounts by banking agents.
 
Separately, cybersecurity firm UpGuard disclosed in September 2025 that an exposed third-party cloud database contained more than 273,000 Indian banking records, including over 6,000 entries linked to Bank of Baroda. Reports at the time said there was no evidence that the Bank's internal systems had been compromised.
 
Bank of Baroda said its investigation remains ongoing and that the independent forensic assessment will determine the precise nature and extent of the incident.
 
You may also want to read...
 
 
Comments
Kamal Garg
2 weeks ago
I fail to understand how when all major banks/all PSU banks have shifted their servers to "bank.in" domain, how can there be a breach into their system. And how can there be a weak password (originating from BoB side/employee side or customer side - must be from BoB side only). By the way, BoB net banking is one of the worst net banking system among all PSU banks and still, if it can be hacked, then, what would happen to other banks.
HDFC Bank Board Penalises CEO, CFO over MSRDC Deposit Deal; Says It Was 'Business Overreach', Not Fraud
Moneylife Digital Team 27 July 2026
Following an internal review into its arrangements with Maharashtra State Road Development Corporation (MSRDC) for mobilising deposits in 2017 and 2021, the board of HDFC Bank Ltd has imposed a monetary penalty of ₹1 lakh each on its...
Moneylife Foundation Study Urges RBI To Cap Borrowing Costs and Limit Multiple Digital Loans
Moneylife Digital Team 24 July 2026
Can a borrower legally end up paying borrowing costs equivalent to 365% a year while simultaneously servicing half a dozen or more digital loans? According to a new study by Moneylife Foundation, the answer is yes—and it stems from...
Kerala HC Flags Plight of Co-op Banks Whose Mirror Accounts Are Frozen for Cyberfraud by a Few Customers
Praisy Thomas (Bar  and  Bench) 17 July 2026
The Kerala High Court recently took note of the difficulties faced by co-operative banks when entire mirror accounts held by them with commercial banks are frozen amid cyber fraud investigations into some of the account holders...
Gen Z Is Reshaping India's Retail Credit Market with Earlier Borrowing, Faster Spending and Quicker Credit Expansion: TransUnion CIBIL
Moneylife Digital Team 10 July 2026
Gen Z consumers are transforming India's retail credit landscape by entering the formal credit system earlier, spending more aggressively after receiving their first credit card and expanding into multiple credit products at a much...
Free Helpline
Legal Credit
Feedback